Skip to main content
IoTFlows - Return to homepage

Command Palette

Search for a command to run...

View as Markdown

Limit which machines a member can see

Grant a member access to specific machines instead of the whole fleet.

You need to be an Organization Owner or Organization Administrator. Everyone else does not see the control at all. See Roles and permissions.

Machine access is a per-person list of the machines someone is allowed to see. Each machine on that list is an allowed asset. The list is empty by default, and an empty list means no restriction: the member sees every machine in the organization.

You do not need machine access if everyone should see everything. It is a restriction, not a requirement, and an organization that never touches it is configured correctly.

What machine access controls

Machine access is managed from the member directory at /members. Each member row carries a control between the person's role and the pencil icon:

What the control showsWhat it means
All machines, on a dashed pill with a globeThe list is empty. This member sees the whole fleet
Up to three machine avatars, then a count of the rest, such as +4The member is restricted to those machines

The restriction applies everywhere, not only to the Assets page. It narrows the machine pickers too, so a restricted member cannot choose an off-list machine when building a report or creating a work order.

Machine access never adds a permission. It can only take machines away from what the person's role already allows.

Grant access to specific machines

  1. Go to /members.
  2. Find the member's row and select the machine-access control on it. The Machine access dialog opens, with that person's name, username, and email at the top.
  3. Use Search machines to find a machine by name or by identifier, or scroll the list.
  4. Select each machine the person should see. A selected machine gets a blue check and the list header counts it, for example Machines · 4/27 selected.
  5. Select Done.
The Machine access dialog, opened from a member row. The member's avatar, name, username, and email sit at the top, above a blue note marked 1 reading Access restricted to 4 selected machines. Deselect all to grant access to every machine. Below it a Search machines field, a list header reading Machines · 4 of 27 selected, and a scrolling list of machines, each with a photo, a name, an identifier, and a circle on the right. A block of four consecutive rows, marked 2, is highlighted blue with a filled blue check. Close and Done sit at the bottomGranting a member access to specific machines.

Is there a Save button?

No. Each machine saves the moment you select it, and a toast confirms it: "Access to Haas VF-2 granted". Close and Done do the same thing, which is to close the dialog. Closing it does not discard anything.

Grant machine access by cell, not by a person's current assignment. An operator restricted to one machine files a support ticket every time they cover for someone, and the administrator ends up granting the whole fleet anyway. Restrict a press operator to the six presses in their cell, not to the one press they ran last week.

If a grant fails, the toast reads "Failed to update machine access" and the machine goes back to unselected, because nothing was saved. Try it again, and if it keeps failing, contact IoTFlows.

Revoke access

  1. Open the Machine access dialog on the member's row.
  2. Select a machine that is already highlighted. The check clears, and the toast reads "Access to Haas VF-2 revoked".
A cropped detail of the Machine access list. One row is mid-revoke: its blue highlight has cleared and a small spinner sits where the blue check was. The rows above and below it stay highlighted blue with filled checksRevoking access to one machine.

To lift the restriction entirely, deselect every machine. The note at the top of the dialog switches to "No machines selected. This member can access all machines", and the directory row goes back to reading All machines.

Removing a member is a different job, and it removes their access to everything rather than narrowing it. See Change roles and remove members.

How access interacts with roles

A role says what someone can do. Machine access says which machines they can do it to. The two are set separately and both apply.

RoleMachine access
Organization OwnerCan be restricted, but do not. The Owner is the billing and ownership role and needs the whole fleet
Organization AdministratorCan be restricted. Administrators still manage machine access for everyone, including themselves
Organization MemberThe usual target. A Member restricted to Haas VF-2 classifies downtime there and cannot see Brother S700X1
Organization ObserverCan be restricted. Read-only on a shorter list

Changing someone's role does not change their machine access, and clearing their machine access does not change their role. A Member promoted to Administrator keeps the same four machines until you clear the list.

For what each role can do, see Roles and permissions.

What a restricted member sees

A restricted member sees a smaller fleet, with no indication that anything was filtered out. There is no banner, no count of hidden machines, and no request-access control.

The Assets page as a member restricted to four machines. Four machine cards fill a grid that holds twenty-seven for an unrestricted member, and the tiles above them — uptime, utilization, downtime, and 3 of 4 machines producing — are computed from those four only. Nothing on the page states that machines are hiddenWhat a restricted member sees. A machine that 'disappeared' is usually this.

A machine that "disappeared" is the first report you will get, and a machine missing from a report or work-order picker is the second. Both have the same cause, so check machine access before you treat either as a data problem.

Open the member's row at /members and read the machine-access control. If it shows a stack of avatars rather than All machines, the machine was not lost. For everything else that makes a machine look wrong, see Troubleshoot monitoring.

See also

Previous
Change roles and remove members

How to work the IoTFlows member directory at /members: one search field covering teams and members, the row controls that change a role and remove someone, and what removal leaves behind. Changing a role opens the Edit member role dialog and reports "Member role changed to" the new role. Removing opens the Remove member dialog, and if the person is the last administrator of something inside the organization, a second step asks whether to keep or delete what they administer. A removed member loses access to everything, and their open work orders stay open and become unassigned. The dashboard has no dedicated transfer-ownership control: ownership moves by setting another member's role to Organization Owner.

Next
Create and manage teams

How to create and run an IoTFlows team: a named group of members that boards, chats, and work-order assignment can point at instead of naming people one at a time. Teams live in the Teams section of the member directory at /members, and each team has its own page at /members/teams/<team-uuid>. Create Team asks for a team name and a team handle, checks the handle for availability as you type, then asks you to pick at least one other member; you are added automatically. The team page renames the team and edits the handle in place, adds and removes members, promotes members to team owner, and carries Leave Team and Delete Team. Deleting a team needs a team owner or an Organization Owner or Administrator. There is no team image control in the web dashboard: a team gets a colored avatar automatically.